Database/Kernel, userspace & hypervisor

Microsoft Hyper-V: vmswitch fails to validate guest OID requests
CVSS 9.9CVE-2021-28476Kernel, userspace & hypervisorcurated
Impact
vmswitch fails to validate guest OID requests - guest reads arbitrary host kernel memory or crashes the host; the highest-rated Hyper-V escape class
Who can reach it
Tenant VM guest
What to do
Windows update + host reboot with live-migration
References
Related entries
- Microsoft Hyper-V: Hyper-V elevation of privilege, exploited in the wildCVE-2024-38080 · Microsoft Hyper-VHigh
- Microsoft Hyper-V: Heap-based buffer overflow in the NT Kernel Integration VSPCVE-2025-21333 · Microsoft Hyper-VHigh
- Microsoft Hyper-V: Use-after-free in the NT Kernel Integration VSP - elevation of privilege, exploited in the wildCVE-2025-21334 · Microsoft Hyper-VHigh
- Microsoft Hyper-V: Use-after-free in the NT Kernel Integration VSP - elevation of privilege, exploited in the wildCVE-2025-21335 · Microsoft Hyper-VHigh
- Incus: instance snapshots bypass restricted.containers.lowlevel, giving command execution on the hostCVE-2026-48751 · Incus (instance snapshots ignore restricted.containers.lowlevel)Critical
- VMware ESXi (OpenSLP): Use-after-free in OpenSLP on port 427 - unauthenticated remote code execution on the hypervisorCVE-2020-3992 · VMware ESXi (OpenSLP)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.